Key Recovery Process
Chapter
22
Setting Up Key Archival and Recovery
727
Key Recovery Agent Scheme
The key recovery agent scheme consists of configuring the Data Recovery Manager to
recognize a fixed number of key recovery agents (a minimum of one) and
specifying how many of these agents are required to authorize a key recovery
request before the archived key is restored. Each recovery agent provides the Data
Recovery Manager with a password, which it uses to generate a unique PIN; the
Data Recovery Manager uses the PIN to protect its storage key pair, which in turn
protects users’ keys.
The Data Recovery Manager tracks the key recovery agent password for each agent
and allows you to facilitate changing agents’ passwords; you do not have direct
access to these passwords or the actual storage key password. Each password
retrieves only a part of the private storage key.
You first specified the key recovery agent scheme when you installed the Data
Recovery Manager.
Changing the Key Recovery Agent Scheme
You can change the total number of key recovery agents for a Data Recovery
Manager and the number of key recovery agents required to retrieve an end user’s
encryption private key from the Data Recovery Manager’s key repository.
To change the key recovery agent scheme:
1.
Access the CMS window (see “Logging In to the CMS Window” on page 333).
2.
Click the Configuration tab.
CAUTION
The PKCS #12 package contains the private key. To minimize the
risk of key compromise, the recovery agent must use any secure,
out-of-band means to deliver the PKCS #12 package and password
to the key recipient. As an administrator, you should recommend
the recovery agent to use a good password for encrypting the PKCS
#12 package, and also consider setting up an appropriate delivery
mechanism.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.01
Page 1: ...Installation and Setup Guide Netscape Certificate Management System Version6 01 May 2002...
Page 22: ...22 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 32: ...32 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 160: ...160 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 776: ...776 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 807: ...807 Part 5 Appendix Appendix A Certificate Download Specification...
Page 808: ...808 Netscape Certificate Management System Installation and Setup Guide May 2002...
Page 830: ...830 Netscape Certificate Management System Installation and Setup Guide May 2002...